Vulnerabilities > Pandasecurity > Panda Antivirus

DATE CVE VULNERABILITY TITLE RISK
2009-12-07 CVE-2009-4215 Permissions, Privileges, and Access Controls vulnerability in Pandasecurity products
Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.
local
low complexity
microsoft pandasecurity CWE-264
7.2
2008-12-12 CVE-2008-5536 Improper Input Validation vulnerability in Pandasecurity Panda Antivirus 9.0.0.4
Panda Antivirus 9.0.0.4, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
network
pandasecurity microsoft CWE-20
critical
9.3